Full Breakdown
ASOS Push Notification Hack Prompts Investigation
By Drooid · · How we work
Core Event: Unauthorized Push Notification Targets ASOS Customers
The message included a link to a Telegram account and urged recipients not to engage with it. The company restricted access to the notification platform and engaged internal and external advisers, as well as relevant authorities.
Background & Context: Recent Wave of UK Cyber Attacks
The incident follows a broader pattern of cyber intrusions affecting major UK firms in 2025-2026, including ransomware attacks on Jaguar Land Rover, Marks & Spencer, Harrods, the Co-op food chain, and a data-theft breach at Manchester Airports Group that exposed 8.7 million customers’ details. ASOS, founded in 2000, serves 17 million active customers worldwide and generated £2.48 billion in revenue while posting a net loss of £298 million for the twelve months to the end of August 2025.
Data & Statistics
- Share-price impact: ASOS shares fell almost 15 % in early trading on October 6, later recovering to a net decline of nearly 10 % by mid-afternoon.
- Customer base: 17 million active shoppers worldwide.
Official Statements & Responses
- ASOS: Stated that its website and app continued to operate normally and that it was working with specialist advisers and authorities. The company emphasized that protecting customers “is our priority” and pledged further updates once more information is confirmed.
- National Cyber Security Centre (NCSC): Offered assistance to ASOS, advising users to ignore the push notification, avoid clicking the Telegram link, and consider enabling two-step verification.
- Information Commissioner's Office (ICO): A spokesperson indicated that the regulator had not yet received a formal report on the matter.
Conflicting Reports & Gaps
- Perpetrator identity: No source has identified the actors behind the notification; investigations remain ongoing.
- Scope of impact: While ASOS acknowledges possible access to basic personal data, it has not quantified how many of its 17 million customers received the alert or how many records were actually accessed.
- Motivation: The message’s demand for engagement suggests extortion, but the exact motive and any financial demands have not been disclosed.
What’s Next
Customers are advised to monitor account activity, update passwords, and enable two-step verification.
Verbatim Quotes
- “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” — Dear Asos, company spokesperson
